Site navigation

Scotland’s Prosecution Service Suffers Third-party Data Breach

Elizabeth Greenberg

,

scotland prosecution service data breach
“These types of third-party cyber-attacks are becoming more common because they allow attackers to reach high value organisations by targeting lower down the supply chain,” William Wright, CEO of Closed Door Security, said.

Scotland’s prosecution service, the Crown Office and Procurator Fiscal Service (COPFS), has suffered from a third-party data breach, the service reported.

The COPFS system itself was not breached, the service said, and there is currently no evidence that the incident has impacted confidential casework or the operational work of the Service.

“Last year, COPFS participated in an online data maturity assessment organised by the Scottish Government and managed by an external supplier. The information affected is limited to employment-related information connected with that survey, such as names, roles and work email addresses,” the COPFS said in a notice of the breach.

The third-party supplier became aware of suspicious activity on 5 August and began to investigate the incident, and then took steps to secure affected systems.

The investigation is ongoing, and the COPFS says it will continue to provide updates as new information emerges.

“This could end up being a very serious security incident, which could pose a genuine threat to employees of the COPFS,” William Wright, CEO of Closed Door Security, said.

“Given the assessment was organised by the Scottish Government, other departments could also be impacted. If this is the case, the government needs to inform impacted parties as a priority.

“These types of third-party cyber-attacks are becoming more common because they allow attackers to reach high value organisations by targeting lower down the supply chain.

“They also reinforce the importance of organisations always vetting the security of suppliers. This should go beyond standard questionnaires about security practices, to seeing the results of physical tests, such as penetration testing.


Recommended reading


“Even though the number of affected individuals is relatively low, the information can be used to craft targeted spear phishing campaigns and could allow attackers to breach COPFS accounts and systems, which likely contain sensitive legal information.

“Given the nature of the work performed by COPFS, these details could also be used to threaten individuals working on criminal cases.

“Employees need to be acutely aware of the risk of phishing going forward: credentials need to be changed, passwords should be updated, and the COPFS should review its own systems to ensure the attackers don’t use the information obtained to launch further attacks.”

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far